Enter the figures you know.
Capture current and prior-year data once, against a structured question and clear rationale.
Enterprise-wide risk assessment software
Complete your enterprise-wide financial crime risk assessment (EWRA), also known as a business-wide risk assessment (BWRA), with scoring, evidence, controls and reporting connected as you work. The assessment writes the report as you complete it. Built for payments businesses wherever they operate; legal practices have their own firm-wide framework.
Demo: sample data, no sign-up. See the report it produces.
Cross-entity comparison across 2 entities.
We have been there
We hear the same story: an organisation hires expensive consultants, spends months documenting requirements and receives a complicated Excel workbook that starts going stale as soon as it is delivered. We have been there.
Use aggregate information you should already have to hand. Start with a tested framework, configure it yourself and get on with the assessment.
Standalone from day one
EWRA works out of the box. Start with a structured framework and sector-specific questions, configure it for your organisation and enter aggregate information you should already have to hand. No data pipeline or systems build is required.
No lengthy integration programme or consultant-led setup is needed to get started.
The methodology was built by a practitioner, has been used in more than one regulated business and across entities in different countries, and has been refined through independent review and regulatory scrutiny.
Intuitive by design
A hammer’s shape tells you where to hold it and which end does the work. Software should offer the same clear cues. That’s affordance: familiar controls, obvious next steps and results you can see.
People who use EWRA have started without training and asked very few questions. The most common comment is that it is easy to use. Their feedback is that it makes a demanding, often unwelcome process feel straightforward to complete.
Visible progress, question by question
Capture current and prior-year data once, against a structured question and clear rationale.
Percentage change, calculated score and colour-coded risk signal appear immediately, with the rationale kept visible.
The result flows into the risk table and overall assessment without a separate reporting step.
One answer. An immediate signal. One less section to assemble later.
Use structured questionnaires across customers, products, geography, channels and emerging risks, covering money laundering, terrorist financing and sanctions. Each response carries its supporting rationale and evidence, so reviewers can follow how the conclusion was reached.
Evaluate control design and operating effectiveness against clear criteria. Rotunda calculates residual risk consistently while preserving the underlying judgements for review.
Required identification and verification data is collected before account activation.
Run a separate sanctions risk assessment without losing the firm-wide view. Keep sanctions-specific exposure, controls and conclusions distinct from the wider financial crime methodology.
Products, jurisdictions, ownership and transaction exposure
Route assessments through preparation, review, second-line challenge and approval. Comments remain attached to the relevant answer, with dates and decisions preserved in the audit trail.
Review submitted assessments and track decisions across entities.
Compare current and prior assessments side by side. Focus review time on material changes in exposure, controls and residual risk, with the reason recorded.
Export a clear report of the methodology, inputs, scoring, challenge and conclusions. Use CSV for further analysis or Markdown with tools approved by your organisation, and retain the audit history.
Confidential and Proprietary Assessment
Report generated · Completion 77%Sector-specific frameworks
A useful assessment shows how the business is exposed, what controls are in place and how the conclusion was reached. Rotunda keeps those elements connected.
EWRA’s payments framework covers merchants and customers, products, geography, channels and emerging risks, with sanctions assessed on its own terms. It has been used across entities in different countries and is not tied to one regulator’s template; you can adjust the framework and record why. Legal practices get a firm-wide risk assessment framework with legal-sector terminology. More sectors coming soon.
EWRA is the assessment itself, not a general GRC platform. If you need workflow across every category of enterprise risk, this is not that tool. If you need a financial crime risk assessment a reviewer can follow, it is.
Your organisation remains responsible for its risk-based judgement and regulatory obligations.
Choosing your platform
An enterprise-wide risk assessment platform brings the assessment inputs, risk methodology, controls, review and reporting into one workflow. For financial crime work, the purpose is to explain the business’s exposure, assess the controls and document the risk that remains. A score alone is not the assessment.
Rotunda supports this work for payments businesses and legal practices. Start with aggregate information you already hold, complete the structured questions and see the assessment report develop as you go. You can enter the information directly; a systems integration is not required to get started.
The demo uses fictional sample data and needs no sign-up. Follow an assessment through risk questions, controls, review and the generated report. Choose the framework closest to your work.
For the underlying process, read how to do an EWRA or BWRA. For access and current pilot terms, see EWRA pricing.
Practical questions
An enterprise-wide risk assessment (EWRA), also known as a business-wide risk assessment (BWRA), is a business’s own assessment of its exposure to money laundering, terrorist financing and sanctions risk, the controls it relies on and the risk that remains. Legal practices call the same exercise a firm-wide risk assessment. The label matters less than the scope you record. See the practical guide.
No. They are two names for the same assessment. The FCA’s 2025 review uses “business-wide”; many firms and international guidance use “enterprise-wide”. Rotunda uses EWRA.
Yes. Most of our customers are in the UK, and the framework is not tied to one regulator’s template. It has been used across entities in different countries, and the demo’s fictional group includes a UAE branch and an EU entity. Your organisation applies the requirements of its own regulators; EWRA organises the work and the record.
Most people start without it. Guidance sits alongside each question, results update as you answer, and the report builds as you go.
Automatic calculations and reporting do the everyday work. Optional AI assistance can help authorised users explore results and draft summaries. Evidence, risk appetite and final judgements remain with your team. CSV and Markdown exports can also be used with tools your organisation approves.
Adjust the framework to your organisation’s risk profile, recording the rationale for changes and any score overrides.
Detailed assessments are available to authorised users in your organisation. Download your assessment data and reports when needed. Peer benchmarking uses anonymous category-level results, excluding narrative answers, evidence and identifiable firm-level data.
You can enter aggregate information directly. Optional automated feeds are scoped separately under the Integrated option.
Explore the demonstration environment or arrange a focused walkthrough.